Glossary · OT cybersecurity
Network security
Also known as: OT network security
German: Netzwerksicherheit
In cybersecurity, network security is the protection of networks and the data flowing through them against unauthorized access, misuse, manipulation and disruption, using measures such as segmentation, firewalls, secure protocols, access control for devices and monitoring.
- OT security
In one sentence
Network security protects networks and their traffic against unauthorized access, manipulation and disruption with segmentation, firewalls and monitoring.
Example
The plant's network security concept separates each production line into its own zone, uses managed switches with port security and routes all cross-zone traffic through firewalls.
How it applies
- Engineering: In OT, network security starts with segmentation along the Zone and conduit model. Flat networks, where every device can reach every other, let a single infection spread across the plant.
- Commissioning: Switch configurations, VLANs and firewall rules must match the approved network design; deviations introduced during commissioning should be documented and reviewed.
- Operation: Many industrial protocols have no built-in authentication. Network measures often compensate until secure protocol variants can be used.
- Documentation: Network drawings, IP address lists, port and protocol tables and switch configuration backups are security-relevant documents: they must be accurate and also protected, because they give attackers a map of the plant.
Network security vs. protocol security
Network security controls which devices can talk to each other. Protocol security, such as encryption and authentication in OPC UA, protects the content and authenticity of each connection. Both are needed.